Privacy policy
Last updated: 6 September 2026
Mela is a Maltese flashcard app, published by CB Scala, Malta. This policy explains what happens to information when you use it. It is short because the app does very little with your data.
Everything you learn stays on your phone
Mela has no account. There is no email address, no password, no sign-in and no profile. We could not identify you if we wanted to.
Your progress — which cards you have seen, when each one is next due, your streak, your settings and which packs you own — is stored on your device only. It is never uploaded, never synced and never visible to us.
A consequence we state plainly rather than bury: a new phone starts your study history at zero. Packs you have bought come back with “Restore purchases”, because purchases live with your App Store or Google Play account, not with us. If your device backup includes app data, a restored phone will usually keep your progress, but we do not promise it.
What does leave your phone
Anonymous usage data
If you leave “Anonymous usage data” switched on in the Me tab, Mela sends counts and outcomes so we can see which parts of the app help people learn: that a session was started and finished, roughly how accurate it was as a band, which pack it came from, and whether a screen was reached.
It never includes a word you studied, a card you got wrong, anything you typed (the app has no text input), or anything that identifies you or your device.
This is tied to a random identifier created when you install the app. It is not your advertising id and not a device id, and we hold nothing that would let us connect it to a person. Turning the switch off replaces it with a new one, so nothing sent before can be connected to anything after.
Processed by PostHog on servers in the European Union. Kept for 12 months, then deleted.
Crash reports
If the app crashes, a diagnostic report is sent so we can fix it. It contains the error and where in the code it happened. File paths are stripped before sending. It carries the same random identifier and no personal information.
Processed by Sentry on servers in the European Union. Kept for 90 days, then deleted.
Turning off “Anonymous usage data” turns off crash reporting too.
Purchases
If you buy a pack or subscribe, the transaction is handled by Apple or Google. We never see your card details. RevenueCat manages the receipt so the app knows what you own; it receives the same random identifier and nothing else about you. RevenueCat is based in the United States, so this is the one place data leaves the EU. That transfer is covered by the European Commission’s standard contractual clauses.
What Mela never does
- It never asks for your name, email address or phone number.
- It never uses your microphone, camera, contacts or location.
- It never shows advertising and never shares anything with advertisers.
- It never sells data. There is nothing to sell.
Notifications
If you allow them, Mela sends at most two a day, both from your own phone: a reminder at the time you chose, and a note if a streak of three days or more is about to end. There is no push server and we never send you anything about prices or offers. You can turn them off in the Me tab or in your phone’s settings.
Children
Mela is not directed at children under 13 and collects nothing that would identify anyone of any age.
Why we are allowed to do this
Under the GDPR, the anonymous usage data and crash reports rely on your consent — the switch in the Me tab, which you can withdraw at any moment. Handling a purchase relies on performing the contract you entered into when you bought a pack. There is no other processing, and none of it is used to profile you or make a decision about you.
Your rights
You have the right to ask what personal data we hold about you, to correct it, to have it deleted, to object to it being processed, and to receive a copy. In practice there is very little we can act on: we hold no name, no email and nothing that connects the random identifier to you, so we usually cannot find “your” data in order to show it to you.
What you can do yourself is immediate and complete:
- Reset all progress in the Me tab, or delete the app, erases everything Mela has stored on the device.
- Switching Anonymous usage data off stops all further sending and retires the random identifier.
If you want to raise something with us anyway, write to privacy@mela.cbscala.com and we will answer within 30 days. If you are not satisfied, you can complain to the Office of the Information and Data Protection Commissioner in Malta, at idpc.org.mt, or to the supervisory authority in your own country.
Changes
If this policy changes we will update the date above and note the change in the app’s release notes.
Contact
CB Scala, Malta — privacy@mela.cbscala.com